5.1 Compare And Contrast Various Types Of Controls Flashcards
Category
There are hundreds, perhaps thousands, of security controls that organizations can implement to reduce risk. The good news is that you don’t need to be an expert on all the possible security controls to pass the CompTIA Security+ exam. However, you do need to have a basic understanding of control categories and control types. CompTIA lists the following control categories in the objectives:
Managerial
Managerial controls are primarily administrative in function. They are typically documented in an organization’s security policy and focus on managing risk.
Operational
Operational controls help ensure that the day-to-day operations of an organization comply with the security policy. People implement them.
Technical
Technical controls use technology such as hardware, software, and firmware to reduce vulnerabilities.
Preventive
Preventative controls attempt to prevent an incident from occurring.
Detective
Detective controls attempt to detect incidents after they have occurred.
Corrective
Corrective controls attempt to reverse the impact of an incident.
Deterrent
Deterrent controls attempt to discourage individuals from causing an incident.
Compensating
Compensating controls are alternative controls used when a primary control is not feasible.
Physical
Physical controls refer to controls you can physically touch.